Kentico Xperience XSS Fiasco: A Closer Look at CVE-2025-32370!

Kentico Xperience before version 13.0.178 is vulnerable to Cross Site Scripting (XSS). This exploit involves crafting a malicious SVG file, zipping it up, and then uploading it to a target URL. As a result, unsuspecting users get a surprise JavaScript alert. Because nothing says “excitement” like unexpected pop-ups!

Pro Dashboard

Hot Take:

Looks like Kentico Xperience needs a little more “experience” when it comes to handling SVGs safely. Who knew triangles could be so dangerous? If only geometry class had prepared us for this kind of XSS-citing development!

Key Points:

  • Kentico Xperience versions before 13.0.178 are vulnerable to XSS attacks via SVG files.
  • The exploit involves crafting a malicious SVG with embedded JavaScript.
  • This SVG is then zipped and uploaded through a vulnerable endpoint.
  • The exploit author is Alex Messham, and the vulnerability has been assigned CVE-2025-32370.
  • Successful exploitation results in an alert pop-up, demonstrating the XSS vulnerability.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?